Omahub
← All plugins
R

OmaSys

by Rooke Poole

A native Omarchy task manager with live system usage, process search, sorting, and safe process controls.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
00973d3
Scanned
1 month ago
  • medium sudo OmaSys.qml:909

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo and are limited to your own processes.")
  • Docs external_hosts README.md:68

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/rookepoole/omasys.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
00973d3
Reviewed
1 month ago

OmaSys is a well-structured task manager that reads system metrics and lists processes read-only, with a carefully guarded process-signaling helper. The deterministic scan's two 'medium' findings are false positives: the external host is a documented `git clone` URL in the README, and the 'sudo' match is from a comment/string explaining that no elevation is used. The code is transparent, contains no obfuscation, network access, persistence, or destructive behavior beyond its intended, user-confirmed process controls.

  • The plugin can send SIGTERM/SIGKILL/SIGSTOP/SIGCONT to processes, which is inherent to a task manager; however, it validates PID format, rejects PID 1, verifies current-UID ownership, and requires explicit user confirmation, so risk is appropriately mitigated.
  • The deterministic scan flagged a 'sudo' string in OmaSys.qml:909, but review confirms it is part of a user-facing message stating actions are limited to the user's own processes and do not use elevation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rookepoole/omasys --enable
System #bar #quickshell #system

OmaSys

OmaSys is a native task manager for the Omarchy Quattro shell. It adds a compact CPU, RAM, and GPU readout to the bar and opens a full system dashboard with live resource usage, searchable processes, sorting, and confirmed process controls.

Release: 1.0.1 Omarchy: Quattro License: MIT

Highlights

  • Live CPU, memory, GPU, swap, root-disk, network, temperature, load, and uptime metrics.
  • Bar widget with CPU, RAM, and GPU utilization; left-click opens OmaSys and right-click refreshes it.
  • Up to 600 processes sampled every two seconds.
  • Instant filtering by PID, user, executable name, or full command line.
  • Sorting by CPU, memory, name, or PID.
  • Resident-memory, state, age, parent PID, owner, nice value, and command-line details.
  • Confirmed actions for clean end (SIGTERM), force end (SIGKILL), suspend (SIGSTOP), and resume (SIGCONT).
  • Theme-native Omarchy UI with keyboard and pointer controls.
  • No daemon, database, network access, telemetry, package hook, install hook, or privilege escalation.

Requirements

  • Omarchy 4.x with the Quattro shell plugin runtime.
  • Bash, procps-ng (ps), coreutils, and Linux /proc//sys interfaces. These are present on a normal Omarchy installation.
  • Optional: nvidia-smi for NVIDIA GPU utilization. AMD and compatible DRM drivers are detected through gpu_busy_percent. Unsupported drivers display GPU N/A without failing the plugin.

Review before installation

Omarchy plugins run unsandboxed inside the long-lived shell process. Review at least these files before enabling OmaSys:

  • manifest.json — plugin identity, kinds, and entry points.
  • OmaSys.qml — full overlay and process-control UI.
  • BarWidget.qml — compact resource sampler and launcher.
  • scripts/collect-system.sh — read-only system metrics.
  • scripts/list-processes.sh — read-only process sampling.
  • scripts/process-action.sh — current-user ownership check and signal allowlist.

The process-action helper accepts only term, kill, stop, or cont; rejects PID 1; verifies that /proc/<pid> belongs to the current UID; and never invokes sudo, pkexec, or another elevation mechanism.

Validate this checkout

From the repository root:

omarchy plugin validate .
./tests/run.sh

Validation is read-only. The test suite creates one temporary sleep process owned by the current user and ends that test process through the same helper used by the UI.

Install

Install the public release and enable its bar widget:

omarchy plugin add https://github.com/rookepoole/omasys.git --enable

OmaSys declares right as its default bar section. Move it later if desired:

omarchy bar move omasys.task-manager --section right

To review a local checkout before enabling it:

git clone https://github.com/rookepoole/omasys.git
cd omasys
omarchy plugin validate .
./tests/run.sh
omarchy plugin add "$PWD"
omarchy plugin enable omasys.task-manager --section right

Open and control OmaSys

Click the bar readout, or summon it directly:

omarchy-shell shell toggle omasys.task-manager '{}'

Keyboard controls:

Key Action
Type Filter processes
Escape Clear the filter; close when the filter is empty
Up / Down Move the selected process
Page Up / Page Down Move by ten processes
Home / End Jump to the first / last process
F5 Refresh system and process data
Space Pause / resume automatic updates
Delete Confirm a clean end (SIGTERM)
Shift+Delete Confirm a force end (SIGKILL)
Alt+S Confirm suspend (SIGSTOP)
Alt+R Confirm resume (SIGCONT)

Right-clicking or double-clicking a process row opens the clean-end confirmation. Every signal path displays the exact process name and PID before acting.

Safe removal

omarchy plugin remove omasys.task-manager

Removal deletes only the plugin checkout managed by Omarchy and its bar/config reference. OmaSys creates no services, hooks, caches, credentials, logs, or state files, so there is no secondary cleanup step.

Data and privacy

OmaSys reads local kernel and process information only while its UI or bar widget is active. It does not transmit data, persist process lists, record command lines, or contact the network. See SECURITY.md for the detailed trust boundary.

Release and marketplace

OmaSys 1.0.1 is the current release. Version 1.0.0 was validated, exercised in a live Omarchy Quattro session, and submitted to the Omarchy plugin marketplace in the System category with the Bar, Quickshell, and System tags. The detailed runtime evidence is in REVIEW.md, and the publication record is in PUBLISH_CHECKLIST.md.

The marketplace publishing guide requires a public GitHub repository, a valid root manifest, README, license, and safe installation/removal. See the Omarchy Plugins publishing guide and the official Omarchy shell plugin reference.

License

MIT. See LICENSE.